Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Is iPhone actually fine replacement for Android in terms of security? I never owned an iPhone, but I was guessing that it is closed-source proprietary piece of hardware with closed-source proprietary piece of software running, which is perfectly able to be transferring all your data to the vendor and most likely does exactly that.


Security professionals tend to care about open source over closed source much less than many other factors.

Things that seem more important^:

- Well known and vetted data structures/algorithms etc

- Vulnerability history

- Large install base

- well regarded, well funded security team vetting the project

- capacity and history of fighting expensive legal battles on behalf of its users.

Its possible that there are android phones that meet these criteria but there are many that do not. The iphone on the other hand does. So rather than having very specific android phone recommendations its generally easier to just say use iPhone. So much so that most of the security professionals I've talked to view it as the most secure, commonly available computing platform period.

^Not a security professional, but I drink with a couple.


I see. I think there might be some distinction in regards of what different people view as "secure". Say, your phone produced by my company may be completely transparent to me and completely impenetrable to, say, tptacek. As I understand, in that narrative it is considered secure as you (the user) are supposed to trust me (the manufacturer). That's why iPhone is considered secure in comparison to Android, which is similarly backdoored, but in addition more penetrable to tptacek (the 3rd party).

Correct?


No. Closed source binaries are not impenetrable to researchers. For a security audit you have to study the binary in any case so open source is a bonus not a requirement.


I didn't imply otherwise. I'm just wondering how it is iPhone is considered secure when it is happily sharing your data with Apple. Or doesn't it?


It's only sharing stuff with Apple if you allow it.


I've had to provide secured smartphones to an organization, and unfortunately they needed to use Android devices for a specific mission critical application.

iPhones are easy to setup and hard to fuck up. You use DEP and it arrives from the factory with a signed profile for your organization. You deliver it to the user, they sign in, and the MDM takes it from there.

With Android, forget it. They were at the time using LUKS for FDE, and there's no segmentation in the OS. So you need need a third party container solution (either from Samsung or another vendor) to protect your data. So you need a pre-boot password, device passcode, a container password, and possibly more. It's a real shitshow.

Apple lets you take the same level of control that a company would have for free with the Configurator app as well.


Android is so bad that iPhone is probably better, despite all those issues.

The real glaring issue here is that we don't really have good, safe services or devices available to us, especially if you want to stay plugged in (have access to the internet, social media, and necessary tools). Pretty much everything is owned by a corporation or compromised or both.

I'm not really convinced that much is gained by using one browser or phone over another at the end of the day. If someone really wants your information, and you're connected to the world, they'll figure out how to get it.


That's my point. I don't understand how is this recommendation any useful, if I'm not missing anything.

Maybe there is a better security guide for a bit more technical people? With why's and how's, explaining what are the real issues and causes of some practice being bad, and what are the possible solutions to it. Why is Android bad? Is it solved by stripping out google services? How do you do it properly? Is it solved by replacing an Android phone with iPhone? Etc. Without any of "jumping into the snake-pit is so bad, that jumping straight into the fire is probably better". Probably better, huh.


One thing to think about is the cost of exploits. [1]

It could be the case that iPhone users are more high value targets. IMHO It's more likely iPhone exploits are just harder to come by. (not impossible, just tougher)

[1] https://arstechnica.com/security/2016/09/1-5-million-bounty-...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: